A proof of concept is available for CVE-2026-14669, a CVSS 8.8 heap-based buffer overflow in PostgreSQL's to_char(timestamptz) date/time formatting path. Improper validation of session timezone-abbreviation length permits an authenticated attacker able to set the session timezone over a normal SQL connection to corrupt memory in the database server process, potentially causing denial of service or executing code as the operating-system account that runs PostgreSQL.
Published exploit details describe using the overflow to disclose heap and PIE-base pointers, forge a MemoryContextCallback, and invoke system during MemoryContextReset() cleanup. PostgreSQL versions 14 through 18 are affected before their respective fixed releases; organizations should identify exposed instances and promptly upgrade to the patched versions in the vendor security bulletin, particularly where untrusted users can establish SQL sessions or alter session settings.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
A proof of concept for exploiting CVE-2026-14669 became available, demonstrating the risk of exploiting the PostgreSQL timezone-formatting flaw.
A fix associated with commit 3d724bf4fde67a2931733a5143b7d6c12b23990c added a length check before copying timezone-format values and returns a DATETIME_VALUE_OUT_OF_RANGE error when the value is too long. Patched releases are PostgreSQL 18.5, 17.11, 16.15, 15.19, and 14.24 or later.
CVE-2026-14669 was identified as a heap-based buffer overflow in PostgreSQL's to_char(timestamptz) timezone-abbreviation handling. An attacker able to set the session timezone could corrupt server-process memory, potentially causing denial of service or code execution as the PostgreSQL operating-system user.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
acn.gov.it
Open sourcecvereports.com
Open sourcesecurity.alpinelinux.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.